Skip to main content

run_sumcheck

Function run_sumcheck 

Source
pub fn run_sumcheck<F, P: PackedField<Scalar = F>, Channel: IPProverChannel<F>, A: Allocator>(
    public_folded: &FieldVec<P, A>,
    hidden_folded: FieldVec<P, A>,
    public_monster: &FieldVec<P, A>,
    hidden_monster: FieldVec<P, A>,
    shift_ind_eval: F,
    public_words: &[Word],
    r_j: Vec<F>,
    gamma: F,
    channel: &mut Channel,
    alloc: &A,
) -> ShiftOutput<F>
where F: BinaryField,
Expand description

Executes the phase-2 sumcheck over the witness, with a sparse first round.

§Overview

The witness and the constraint-matrix multilinear are each given as a (public, hidden) segment pair. The top word-index variable selects the segment.

The first round binds that selector without materializing the mostly-zero combined buffers. After the selector challenge, the segment pairs fold into single dense buffers, and a shared dense-product prover proves the remaining rounds. So every round message is identical to what a fully dense prover would send.

After the sumcheck, this derives the witness evaluation from the combined evaluation: it evaluates the public segment directly (cheap, like the verifier does), subtracts its padded contribution, and scales.

It also divides the three bit-index factors back out of the constraint-matrix evaluation, leaving the wiring evaluation the verifier’s claim is about.

§Returns

The sumcheck’s concatenated challenges with the witness evaluation, and the wiring evaluation for the caller to send.